USB Removable Media Exfiltration via File Copy or xcopy/robocopy
Detects high-volume file writes or the use of common command-line copy utilities (xcopy, robocopy, copy) targeting removable drive paths (E-G:). This behavior is often indicative of data staging or exfiltration activities.
SentinelOne

